Tag

Zero Trust

Understand the Zero Trust security model, which operates on the principle of never trust, always verify. Posts cover Zero Trust architecture, identity verification, micro-segmentation, least-privilege access, and practical steps for implementing Zero Trust frameworks across enterprise environments.

posts

CISA Cybersecurity Guidelines

CISA Cybersecurity Guidelines: What They Mean for You

The Federal Agency Most Hackers Wish You'd Never Heard Of In January 2024, CISA — the Cybersecurity and Infrastructure Security Agency — issued an emergency directive after threat actors exploited vulnerabilities in Ivanti VPN products to infiltrate multiple federal agencies. The directive gave agencies 48 hours to disconnect affected devices.

Carl B. Johnson Jul 02, 2026 5 min read
Remote Work Cybersecurity Tips

Remote Work Cybersecurity Tips That Actually Work

Your Home Office Is Now the Attack Surface In 2023, a single remote employee at MGM Resorts answered a social engineering call from a threat actor impersonating IT support. That one interaction led to a ransomware attack that cost the company over $100 million in losses. The attacker didn'

Carl B. Johnson Jul 01, 2026 5 min read
Third Party Risk

Third Party Vendor Cybersecurity Risk: A 2026 Guide

In early 2024, a breach at Change Healthcare — a subsidiary of UnitedHealth Group — crippled pharmacies and hospitals across the United States for weeks. The attack didn't start at a hospital. It started at a third party vendor. A single set of compromised credentials on a system without multi-factor

Carl B. Johnson Jun 24, 2026 5 min read
CISA Cybersecurity Guidelines

CISA Cybersecurity Guidelines: What Actually Matters

Most Organizations Read CISA's Advice — Then Ignore the Hard Parts In 2023, the City of Dallas got hit with Royal ransomware. Services went down. Police dispatch systems broke. Recovery took weeks and cost millions. The attack vector? The kind of basic intrusion that CISA cybersecurity guidelines have warned

Carl B. Johnson Jun 20, 2026 5 min read
Shadow IT Risks

Shadow IT Risks: The Threats Hiding in Your Network

A Single Spreadsheet Cost One Hospital $3 Million In 2023, a healthcare employee uploaded patient records to an unauthorized cloud spreadsheet tool to "make things easier" for her team. Nobody in IT knew about it. No encryption, no access controls, no audit trail. When that tool suffered a

Carl B. Johnson Jun 20, 2026 6 min read
Mobile Device Security Policy

Mobile Device Security Policy: Build One That Works

A Single Lost Phone Cost This Company $4.9 Million In 2023, a healthcare organization reported a breach to HHS that started with one unencrypted smartphone left in an airport lounge. Patient records, internal credentials, VPN configurations — all exposed. The settlement and remediation costs were staggering. And here's

Carl B. Johnson Jun 18, 2026 6 min read
SaaS Security

SaaS Security Best Practices Your Team Needs in 2026

The Average Company Runs 130 SaaS Apps — And Secures Maybe Half In early 2024, a threat actor breached Snowflake customer environments — not by exploiting a zero-day, but by using stolen credentials harvested from infostealer malware. The result? Hundreds of millions of records exposed across companies like Ticketmaster and AT&

Carl B. Johnson Jun 10, 2026 6 min read
Cloud Storage Security Risks

Cloud Storage Security Risks Your Team Is Ignoring

A Single Misconfigured S3 Bucket Exposed 540 Million Facebook Records Back in 2019, researchers at UpGuard discovered that two third-party Facebook app developers had left hundreds of millions of user records sitting in publicly accessible Amazon S3 buckets. No hacking required. No sophisticated exploit. Just wide-open cloud storage that anyone

Carl B. Johnson Jun 10, 2026 5 min read